Impact
IBM Verify Identity Access Advanced Access Control may allow an information disclosure attack. The CVE description indicates that a flaw could enable an unauthorized user to read data that should be confidential. Because the issue is classified as CWE‑1336, it suggests an authority bypass; however, the exact extent of the data exposed is not specified. Based on the description, it is inferred that an attacker possessing sufficient access could exploit the weakness to gain visibility into protected information.
Affected Systems
Affected products include IBM Verify Identity Access and IBM Security Verify Access, as well as their container counterparts. For the non‑container versions, IBM Verify Identity Access v11.0.3 interim fix and earlier baseline versions (v11.0.0) are affected; IBM Security Verify Access v10.0.9.2 interim fix and earlier baseline versions (v10.0.0) are also impacted. Containers are affected for the corresponding 10.0.9.2 and 11.0.3 interim fixes and their baseline 10.0.0 and 11.0.0 images.
Risk and Exploitability
The CVSS score of 7.5 and EPSS score of < 1% indicate a moderate likelihood of exploitation but limited public exploitation data. The vulnerability is not listed in CISA’s KEV catalog and no known exploits are cited. Consequently, the likelihood of active exploitation is uncertain, but the confidentiality impact warrants precaution. Because the flaw is linked to improper authorization logic, any user with elevated privileges could potentially read disallowed data if the vulnerability is exploited.
OpenCVE Enrichment